Biometric retention schedule
740 ILCS 14/15(a) · Tex. Bus. & Com. Code §503.001 · RCW 19.375 · Effective 2026-07-17
Illinois's Biometric Information Privacy Act (BIPA) §15(a) requires that any private entity in possession of biometric identifiers or biometric information develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying such data. Texas's Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code §503.001) and Washington's My Health My Data Act (RCW 19.375) impose parallel requirements. This page is that policy.
What Afterroar itself holds
Afterroar does not independently collect, store, or process biometric identifiers — no face geometry, no voiceprints, no fingerprints, ever. Government-ID verification is performed by Stripe Identity as an independent controller (see the Privacy Policy). From Stripe Identity we receive back only:
- A pass/fail signal (whether verification succeeded).
- The ID fields Stripe extracted from the presented document — typically name, date of birth, and address; where applicable, an over-18 or over-21 boolean.
We do not receive or retain the biometric image or the biometric template computed by Stripe.
Retention schedule for Afterroar-held artifacts
The pass/fail signal and the extracted ID fields are retained by Afterroar for the shorter of:
- the initial purpose being satisfied — for example, once a Passport identity-verified fact is no longer required for any feature the user participates in; or
- three (3) years from the account holder's last interaction with Afterroar, as measured by the most recent sign-in, Stripe Identity attempt, or verification-referencing feature use.
At the end of the shorter of these two periods, Afterroar destroys the pass/fail signal, the extracted ID fields, and the BiometricConsent record that authorized the underlying Stripe Identity leg. Destruction is performed by database row deletion within the applicable Afterroar Postgres cluster; no separate offline copy is retained.
Stripe Identity — pass-through deletion
The biometric image and biometric template held by Stripe Identity are governed by the Stripe Privacy Policy and Stripe's own retention schedule. Afterroar acts as a pass-through for user deletion requests: on receipt of a written request at privacy@afterroar.me (or via the delete-your-Passport flow at afterroar.me/data), we (a) delete the pass/fail signal, extracted ID fields, and BiometricConsent row Afterroar holds, and (b) instruct Stripe to delete the corresponding underlying biometric data. Stripe's response time and destruction procedures are governed by their policy, not ours; we surface Stripe's confirmation to you when it is received.
Written consent required
Under BIPA §15(b), TX CUBI, and WA MHMDA, informed written consent is required before any biometric processing. Afterroar captures this consent at /verify/identity/consent before every Stripe Identity session. The consent record — user id, disclosure version, timestamp, IP address, and user agent — is retained for the same period as the pass/fail signal and destroyed at the same time; it is the audit artifact for the consent, and its retention is limited to that purpose.
Amendments
This retention policy may be revised. Material revisions will be announced in-app and via email to registered addresses (where you have consented to platform communications), and each version of this policy remains accessible for historical reference. The consent captured at the time of each Stripe Identity session is pinned to the disclosure version in force at that time.
Contact
For questions about biometric-processing artifacts or retention: privacy@afterroar.me
Afterroar is operated by Full Uproar Games, Inc., South Bend, Indiana, USA.